Five Questions to Ask Your Current IT Provider (and What the Right Answer Should Be)

If you ask most business owners whether their IT is being looked after properly, they will say yes without much hesitation. Ask them how they know, and they’ll usually say because their IT provider told them so.

Few directors have the time or the technical background to check this themselves, so the job gets delegated entirely, and it stays delegated until something forces a second look. It is part of why Integy exists in the first place: the business was founded by two engineers who had grown tired of watching bigger providers overpromise and leave someone else to sort out the fallout, and that is still how a lot of our own client relationships start today. Usually it starts with someone finally getting round to asking a question they had been avoiding, not because anything had obviously gone wrong. What turns up is rarely dramatic, more often a licence nobody had switched on or a report that had sat unread for months. Nobody outside the business would have noticed. There just hadn’t been anyone keeping an eye on it.

Here are five questions worth asking whoever looks after your IT, and what a weak answer to each one tends to sound like.

1. Can they show you evidence, or just tell you it is fine?

Anyone can say your systems are secure. Fewer people can show you what that means in practice. Ask to see a report, a benchmark, or a simple before-and-after that reflects your own setup, not a generic slide. It is worth knowing that a provider who describes themselves as “aligned to” Cyber Essentials is not the same as one who has been independently tested under Cyber Essentials Plus, even though the two get used almost interchangeably in conversation. If the only evidence on offer is a confident tone of voice, that is not evidence.

2. Do you hear about problems from them, or do you find them yourself?

The better test of an IT relationship is not how calm things feel. It is who tells you when something is wrong. A provider doing their job properly will flag a lapsed licence, a failed backup, or a slipping security score before you think to ask about it. If every update you get is something you chased, or if the first you heard of an issue was from a client, an auditor, or your own bank, that tells you whose side the visibility sits on.

3. What happens the day your main contact is not available?

Most businesses have one person they call. That person might be excellent, but it is worth asking what happens on the day they are on holiday, off sick, or have simply moved on. Is there someone else who already understands your setup, or would somebody be starting from scratch? A relationship built around a single point of contact, however good that person is, quietly becomes a single point of failure for your business too.

4. When did they last suggest something you had not asked for?

A provider who only ever responds to requests is running a ticket queue, not looking after your IT. Think back over the last six months. Has anyone flagged a risk, an unused licence, or a better way of doing something without you raising it first? If every conversation started with you, the relationship is reactive by design, and reactive is usually the mode in which problems get noticed only after they have already cost something.

5. If you left tomorrow, how much would leave with them?

Ask what would happen if you switched providers next month. Is your setup documented somewhere you could hand over, or does most of it live in someone else’s head or inside tools only they can access? NCSC’s own guidance on choosing an IT partner makes a similar point: a trustworthy provider makes this kind of information easy to get, not something you have to fight for. A relationship that has never had to answer this question honestly has usually made itself hard to leave, not hard to fault.

Why this rarely gets asked

There is a reason none of this feels natural to raise. Most businesses would scrutinise a new supplier, a big customer contract, or a bank far more carefully than they scrutinise the people holding their systems and data together. It is telling that in the government’s most recent Cyber Security Breaches Survey, the single most common source businesses named for security advice was their own external IT or cyber security provider, mentioned far more often than any independent body, including the National Cyber Security Centre itself. Few of those same businesses had ever formally reviewed the risk that provider represented. We are, in other words, unusually willing to trust the one relationship we have never tested.

Where this leaves you

This doesn’t mean your current provider is doing badly. Plenty are doing this well, and a good answer to all five should leave you reassured rather than rattled. But if two or three of these are hard to answer, or you find yourself guessing where you should have evidence, that is worth figuring out before it costs you something.

It is also usually a much smaller job than it sounds. A short, independent look at where things are does not commit you to anything, and it is often how the relationships we are proudest of started, before anything had gone wrong.

If you would rather start with the more technical version of this list, the one covering backups, patching, and Secure Score, we covered that ground in an earlier piece. And if you would like a clear, no-obligation starting point of your own, our free Microsoft 365 assessment benchmarks your setup against Cyber Essentials and CIS at no cost.

Either way, understanding where you stand is a different exercise from deciding to change anything, and it is one every business is entitled to carry out without waiting for something to break first.